• Hackers demanded 6,000 Monero (XMR), about $3 million, threatening to sell stolen Revolut data.

• At least 680 Revolut accounts exposed, including passports, KYC photos and transaction records.

• Attackers used a government-domain email to pass fraudulent data requests past Revolut checks.

A $3M Ransom in Monero

Hackers behind the Revolut data breach have moved from theft to extortion, publicly demanding 6,000 Monero (XMR) — roughly $3 million — in exchange for keeping stolen customer records off criminal marketplaces. The group, calling itself “iamnotavillain”, published its demand on Wednesday and threatened to sell the dataset to other criminal organizations if the fintech declines to pay. At least 680 customer accounts are affected. The exposed records include passports, driving licenses, identity-verification photos used in KYC checks and detailed transaction histories — documents that, unlike passwords, cannot be rotated once they leak. Revolut, which has not disclosed exact figures, describes the number of affected customers as “limited” and says it has received no direct ransom approach. The choice of Monero fits the crime: Monero (XMR) is a privacy coin that conceals transfer amounts and counterparties by default, making payment tracing far harder than on transparent ledgers such as Algorand (ALGO) or Stellar (XLM), a key reason extortion crews repeatedly settle on it. Because Monero's design obscures even whether a payment occurred, Revolut would struggle to verify compliance — a built-in advantage for the extorter. The deeper liability is linkage, not the files themselves: a verified identity attached to demonstrable on-chain wealth turns an anonymous wallet into a named, locatable target. Leaked documents also feed impersonation, letting fraud rings open accounts in a victim's name or run convincing social-engineering plays. The attackers' leverage is urgency and fear — a lever closer to classic phishing than to the market's familiar FOMO-driven trading psychology — and once these documents circulate, no password reset claws them back.

Fake Government Requests Opened the Door

Revolut's own account of how the records left its systems points to process failure rather than a technical exploit. Attackers used an email account on an official government domain to submit fraudulent emergency information requests. Those requests cleared the company's internal verification checks, and staff handed over the data before the impersonation was detected. The company has characterized the incident as “a sophisticated external impersonation fraud” and says it blocked the fraudulent address as soon as it learned of the scheme. Its core systems and customer funds, it maintains, were never compromised, and it has notified government bodies, law enforcement and regulators. Unconfirmed claims add another layer: the group says it also breached an Italian government email system and ran blockchain analysis to identify Revolut customers holding large amounts of crypto — an assertion the company has not corroborated. Mark Karpelès, the former Mt. Gox chief, confirmed he was among those affected, publishing a Revolut notice indicating that his Bitcoin transaction details had leaked. On-chain investigator ZachXBT assessed the operation as deliberate rather than opportunistic, aimed at users with significant wealth. The physical-security dimension is measurable: Chainalysis documented $124.1 million in losses across 52 confirmed “wrench attack” incidents in 2026, while CertiK logged 33 of 52 confirmed cases in France in the first half of the year, with home invasions rising from one in H1 2025 to 20. Both firms caution their figures understate the true toll, since many victims never report these attacks. For ordinary users, the risk is long-tail: any notice about an account opening or authorization in their own name now deserves scrutiny, because identity theft built on leaked KYC files can surface months later.

KYC Data Becomes the Attack Surface

The thread connecting the ransom note and the breach method is that identity data, not coins, was the prize — and the vulnerability was process, not code. The European Banking Authority's June 2026 risk assessment already ranks cybersecurity and data security as the leading driver of operational risk in banking, ahead of fraud, a hierarchy this incident illustrates precisely. The FCA's consumer research finds 73% of UK crypto users acquire assets through centralized platforms, meaning exposure concentrates exactly where KYC data lives. For COINOTAG's desk, the lasting lesson is data minimization plus independent verification of official-looking requests; some customers will also reassess how much identity-anchored exposure they keep on centralized venues versus self-custody routes such as Bitcoin DeFi, a custody consideration our Best Crypto Exchanges guide now covers in detail.